We process business and personal information belonging to our customers and employees and because of this, we are subject to numerous federal, state, local, and foreign laws, orders, codes, regulations, and regulatory guidance regarding privacy, data protection, information security, and the processing of personal information and other content (collectively, "Data Protection Laws"), the number and scope of which are changing, subject to differing applications and interpretations, and may be inconsistent among countries, or conflict with other rules, laws, or Data Protection Obligations (defined below). These laws and regulations include HIPAA, which establishes a set of national privacy and security standards for the protection of PHI by health plans, healthcare clearinghouses and certain healthcare providers, referred to as covered entities, and individuals and entities that perform services for them which involve the use, or disclosure of, individually identifiable health information, known as business associates and their subcontractors. We are considered a business associate under HIPAA, and we execute business associate agreements ("BAAs") with our customers, subcontractors, and trusted suppliers. HIPAA requires covered entities and business associates, such as Weave, and their covered subcontractors to develop and maintain policies and procedures with respect to PHI that is used or disclosed, including the adoption of administrative, physical and technical safeguards to protect such information.
Failure to comply with HIPAA could subject us to direct civil liability by the Department of Health and Human Services' Office for Civil Rights ("OCR"). In the event of an information security incident affecting PHI or other violation, OCR could require us to pay a civil monetary penalty and enter into a Corrective Action Plan that could cause to incur substantial compliance costs.
Similar Data Protection Laws are in place in Canada, including the PIPEDA. Failure to comply could subject us to investigation and monetary penalty by the Office of the Privacy Commissioner of Canada.
In addition, experiencing a breach of personal information or PHI, or failing to comply with HIPAA could also subject us to contractual liability under our BAAs with our covered entity customers and damage our reputation which might hurt our ability to retain existing customers or attract new customers.
We expect that there will continue to be new Data Protection Laws and Data Protection Obligations, and we cannot yet determine the impact such future Data Protection Laws may have on our business.
We are also subject to the terms of our internal and external privacy and security policies, codes, representations, certifications, industry standards, publications, and frameworks, which we refer to as Privacy Policies, and obligations to third parties related to privacy, data protection, and information security ("Data Protection Obligations").
The requirements or obligations of the regulatory framework for privacy, information security, data protection, and data processing worldwide is, and is likely to remain, uncertain for the foreseeable future, and it is possible that these or other actual or alleged obligations may be interpreted and applied in a manner that is inconsistent from one jurisdiction to another and may conflict with other rules or our practices.
Any significant change in Data Protection Laws or Data Protection Obligations, including without limitation, regarding processing of our users' or customers' data, or regarding the manner in which the express or implied consent of users or customers for the use and disclosure of such data is obtained, could increase our costs and could require us to modify our products or operations, possibly in a material manner, and may limit our ability to develop new services and features that make use of the data that our users and customers voluntarily share, or may limit our ability to store and Process customer data and operate our business.
Data protection legislation is also becoming increasingly common in the U.S. at both the federal and state level. For example, California enacted legislation, the CPRA, which affords consumers expanded privacy protections. The potential effects of this legislation are far-reaching and have required Weave to implement enhanced practices and policies in an effort to comply. Specifically, the CCPA gives California residents expanded rights to request access to and deletion of their personal information, opt out of certain personal information sharing and receive detailed information about how their personal information is used. The CCPA also provides for civil penalties for violations, as well as a private right of action for data breaches that may increase data breach litigation. In addition, the CCPA has prompted a number of proposals for new federal and state privacy legislation that, if passed, could increase our potential liability, increase our compliance costs, and adversely affect our business. It remains unclear how much private litigation will ensue under the data breach private right of action. Additionally, the CPRA, which became fully effective on January 1, 2023, expanded the rights of California residents with respect to their personal information. The CPRA, among other things, gives California residents the ability to limit use of certain sensitive personal information, further restrict the use of cross-contextual advertising, establish restrictions on the retention of personal information, expand the types of data breaches subject to the CCPA's private right of action, provide for increased penalties for CPRA violations concerning California residents under the age of 16, and establish a new California Privacy Protection Agency to implement and enforce the new law which may result in increased regulatory scrutiny of California businesses in the areas of data protection and security. Moreover, at least 18 other states have created state specific privacy laws. Compliance with any newly enacted privacy and data security laws or regulations may be challenging and cost and time-intensive, and we may be required to put in place additional mechanisms to comply with applicable legal requirements. In addition, the various state privacy laws may limit how we use personal information we collect, particularly with respect to marketing and the use of online advertising networks.
Furthermore, the FTC and many state attorneys general continue to enforce federal and state consumer protection laws against companies for online collection, use, dissemination and security practices that appear to be unfair or deceptive. There are a number of legislative proposals in the U.S., at both the federal and state level and more globally, that could impose new obligations in areas such as e-commerce and other related legislation or liability for copyright infringement by third parties. We cannot yet determine the impact that future laws, regulations, and standards may have on our business.
Change in existing legislation or introduction of new legislation may require us to incur additional expenditures to ensure compliance with such legislation, which may adversely affect our financial condition. We strive to comply with Data Protection Laws and Data Protection Obligations to the extent possible, but we may at times fail, or may be perceived to have failed, to do so. Moreover, despite our efforts, we may not be successful in achieving compliance if our employees, partners, or vendors do not comply with applicable Data Protection Laws and Data Protection Obligations. If our Privacy Policies are found to be inaccurate, incomplete, deceptive, unfair, or misrepresentative of our actual practices-whether in whole or in part-it could have serious consequences. Similarly, a failure or perceived failure to comply with Data Protection Laws or Data Protection Obligations, or a data compromise leading to the unauthorized release or transfer of business or personal information, could also be harmful. Any such issues may increase our compliance and operational costs, limit our ability to market our products or services, and affect our ability to attract and retain customers. They could also restrict or eliminate our ability to process data and lead to enforcement actions, fines, litigation, and significant expenses, including attorney fees. Additionally, they may cause a material adverse impact on our business operations and financial results or lead to other significant harm. Furthermore, any such failure or perceived failure could result in public criticism from consumer advocacy groups, the media, or other sources, potentially causing substantial reputational damage. Our actual or perceived failure to comply with Data Protection Laws, Privacy Policies, and Data Protection Obligations could also subject us to litigation, claims, proceedings, actions, or investigations by governmental entities, authorities, or regulators that could require changes to our business practices, diversion of resources and the attention of management from our business, regulatory oversights and audits, discontinuance of necessary processing, or other remedies that adversely affect our business.